{"data":{"id":"fed07ee7-101d-4e77-abac-10599de5e25b","title":"GHSA-xwg4-73v4-xw9w: nanoid: Integer Overflow or Wraparound","summary":"A flaw in the nanoid library causes an integer overflow (a calculation error where a number wraps around to an unexpected value) when the size parameter exceeds 2^31, permanently breaking the random number generator for the entire process and making all generated IDs return the identical string \"uuuuuuuuuuuuuuuuuuuuu\". This allows attackers to predict session tokens, CSRF tokens (data that prevents forged requests), and other security-critical identifiers by passing a large user-controlled value to the size parameter, which persists until the process restarts.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://github.com/advisories/GHSA-xwg4-73v4-xw9w","publishedAt":"2026-09-01T19:23:45.000Z","cveId":"CVE-2026-73086","cweIds":null,"cvssScore":null,"cvssSeverity":"high","severity":"high","attackType":["other"],"issueType":"vulnerability","affectedPackages":["nanoid@>= 4.0.0, < 5.1.11 (fixed: 5.1.11)","nanoid@< 3.3.12 (fixed: 3.3.12)"],"affectedVendors":[],"affectedVendorsRaw":[],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":"unknown","epssScore":0.00296,"patchAvailable":true,"disclosureDate":"2026-09-01T19:23:45.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"trivial","impactType":["integrity","confidentiality"],"aiComponentTargeted":null,"llmSpecific":false,"classifierConfidence":0.75,"researchCategory":null,"atlasIds":null}}